Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Duration 21 hours
Course Outline
Cluster Setup
- Implement Network security policies to limit cluster-level access
- Leverage the CIS benchmark to assess the security configuration of Kubernetes components (etcd, kubelet, kubedns, kubeapi)
- Configure Ingress objects with appropriate security controls
- Secure node metadata and endpoints
- Limit the usage of and access to GUI elements
- Validate platform binaries prior to deployment
Cluster Hardening
- Restrict access to the Kubernetes API
- Apply Role Based Access Controls to reduce exposure
- Handle service accounts with care, such as disabling defaults and minimizing permissions on newly created ones
- Keep Kubernetes up to date with frequent updates
System Hardening
- Reduce the host OS footprint to shrink the attack surface
- Minimize IAM roles
- Limit external access to the network
- Utilize kernel hardening tools like AppArmor and seccomp appropriately
Minimize Microservice Vulnerabilities
- Establish proper OS-level security domains using tools like PSP, OPA, and security contexts
- Manage kubernetes secrets effectively
- Employ container runtime sandboxes in multi-tenant environments (e.g., gvisor, kata containers)
- Enforce pod-to-pod encryption via mTLS
Supply Chain Security
- Reduce the base image footprint
- Safeguard the supply chain by whitelisting image registries and signing/validating images
- Perform static analysis on user workloads (e.g., kubernetes resources, docker files)
- Scan images for existing vulnerabilities
Monitoring, Logging and Runtime Security
- Conduct behavioral analytics of syscall processes and file activities at both host and container levels to identify malicious actions
- Identify threats across physical infrastructure, applications, networks, data, users, and workloads
- Track all phases of an attack, regardless of origin or propagation method
- Execute deep analytical investigations to identify malicious actors within the environment
- Guarantee container immutability during runtime
- Monitor access using Audit Logs
Requirements
- CKA (Certified Kubernetes Administrator) certification
Audience
- Kubernetes practitioners
Testimonials (3)
basic understanding of container/kubernetes and how they interact features of the openshift plattform
Eric Scholze - NOW IT GmbH
Course - Introduction to Containers, Kubernetes & OpenShift
About the microservices and how to maintenance kubernetes
Yufri Isnaini Rochmat Maulana - Bank Indonesia
Course - Advanced Platform Engineering: Scaling with Microservices and Kubernetes
The training met expectations with its clear explanations, real-world examples, and hands-on labs that made complex topics easy to understand. It provided valuable insights into container orchestration, security, scaling and many other advanced topics.